Total CVEs

150,903

Critical Severity

5,032

High Severity

17,664

Last 7 Days

2,098
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,341 - 2,360 of 47,308 CVEs
CVE-2026-64815 HIGH - 8.1

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files

Vendor: JetBrains
Product: IntelliJ IDEA
Published: Jul 23, 2026
Source: NVD
CVE-2026-64814 HIGH - 8.6

In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session

Vendor: JetBrains
Product: IntelliJ IDEA
Published: Jul 23, 2026
Source: NVD
CVE-2026-64813 CRITICAL - 10.0

In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session

Vendor: JetBrains
Product: IntelliJ IDEA
Published: Jul 23, 2026
Source: NVD
CVE-2026-64812 CRITICAL - 10.0

In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session

Vendor: JetBrains
Product: IntelliJ IDEA
Published: Jul 23, 2026
Source: NVD
CVE-2026-64811 HIGH - 7.8

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration

Vendor: JetBrains
Product: IntelliJ IDEA
Published: Jul 23, 2026
Source: NVD
CVE-2026-64810 MEDIUM - 4.3

In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking

Vendor: JetBrains
Product: IntelliJ IDEA
Published: Jul 23, 2026
Source: NVD
CVE-2026-64809 HIGH - 8.4

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter

Vendor: JetBrains
Product: PhpStorm
Published: Jul 23, 2026
Source: NVD
CVE-2026-64808 HIGH - 8.4

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling

Vendor: JetBrains
Product: PhpStorm
Published: Jul 23, 2026
Source: NVD
CVE-2026-64807 HIGH - 7.8

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration

Vendor: JetBrains
Product: WebStorm
Published: Jul 23, 2026
Source: NVD
CVE-2026-64806 HIGH - 8.4

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter

Vendor: JetBrains
Product: WebStorm
Published: Jul 23, 2026
Source: NVD
CVE-2026-64805 HIGH - 8.4

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling

Vendor: JetBrains
Product: WebStorm
Published: Jul 23, 2026
Source: NVD
CVE-2026-64804 HIGH - 8.4

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling

Vendor: JetBrains
Product: WebStorm
Published: Jul 23, 2026
Source: NVD
CVE-2026-64803 HIGH - 7.8

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK

Vendor: JetBrains
Product: GoLand
Published: Jul 23, 2026
Source: NVD
CVE-2026-64802 HIGH - 7.8

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration

Vendor: JetBrains
Product: GoLand
Published: Jul 23, 2026
Source: NVD

In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default

Vendor: JetBrains
Product: GoLand
Published: Jul 23, 2026
Source: NVD
CVE-2026-61981 MEDIUM - 5.4

Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.

Vendor: QuantumCloud
Product: Simple Link Directory Pro
Published: Jul 23, 2026
Source: NVD
CVE-2026-61973 MEDIUM - 4.3

Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.

Vendor: WooLentor
Product: ShopLentor Pro
Published: Jul 23, 2026
Source: NVD
CVE-2026-61972 MEDIUM - 5.3

Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.

Vendor: WooLentor
Product: ShopLentor Pro
Published: Jul 23, 2026
Source: NVD
CVE-2026-61954 HIGH - 7.5

Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.

Vendor: PayU India
Product: PayU India
Published: Jul 23, 2026
Source: NVD
CVE-2026-61951 CRITICAL - 9.8

Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.

Vendor: themetechmount
Product: TrueBooker
Published: Jul 23, 2026
Source: NVD